Log---
Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrator at 2009-02-14 14:35:42
Microsoft Windows XP Professional Service Pack 3
System drive C: has 106 GB (92%) free of 114 GB
Total RAM: 1022 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:35:46 PM, on 2/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\WINDOWS\system32\wuauclt.exe
E:\New Folder\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Administrator.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://login.yahoo.com/config/login_verify...p;pkg=&owd=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Quick Macros] "C:\Program Files\Quick Macros 2\qm.exe" S
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://www.donutdoors.comO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L.
http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
--
End of file - 8088 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-28 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
MSN Toolbar Helper - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll [2008-12-04 83800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-28 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-28 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
{1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - MSN Toolbar - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll [2008-12-04 83800]
{381FFDE8-2394-4f90-B10D-FC6124A40F8C} - BitDefender Toolbar - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll [2008-11-06 90112]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-02-19 16858112]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-28 136600]
"Quick Macros"=C:\Program Files\Quick Macros 2\qm.exe [2006-06-15 1282048]
"BDAgent"=C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe [2009-01-09 741376]
"BitDefender Antiphishing Helper"=C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe [2008-10-17 69632]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-01-06 290088]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-02-11 399504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"Messenger (Yahoo!)"=C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE [2009-01-23 4363504]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-09-29 122880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe"="C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Documents and Settings\Administrator\temp\TeamViewer3\TeamViewer.exe"="C:\Documents and Settings\Administrator\temp\TeamViewer3\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f50c7a76-ed82-11dd-8eea-001d6053b380}]
shell\AutoRun\command - G:\JDSecure\Windows\JDSecure31.exe
======List of files/folders created in the last 1 months======
2009-02-14 14:35:42 ----D---- C:\rsit
2009-02-14 14:25:41 ----D---- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2009-02-14 14:25:33 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-02-14 14:25:33 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-02-13 22:45:27 ----D---- C:\Program Files\Trend Micro
2009-02-10 14:04:32 ----A---- C:\WINDOWS\bdagent.INI
2009-02-06 16:38:49 ----A---- C:\WINDOWS\ODBC.INI
2009-02-06 16:38:04 ----D---- C:\Program Files\Microsoft ActiveSync
2009-02-06 16:38:00 ----D---- C:\Program Files\Common Files\DESIGNER
2009-02-06 16:37:42 ----D---- C:\WINDOWS\SHELLNEW
2009-02-06 16:37:41 ----D---- C:\Program Files\Microsoft.NET
2009-02-06 16:37:41 ----D---- C:\Program Files\Microsoft Office
2009-02-01 03:00:35 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-02-01 03:00:21 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-01-31 11:02:40 ----D---- C:\Documents and Settings\Administrator\Application Data\Mozilla
2009-01-31 11:02:32 ----D---- C:\Program Files\Mozilla Firefox
2009-01-31 10:55:32 ----D---- C:\Program Files\CONEXANT
2009-01-31 01:06:52 ----A---- C:\WINDOWS\system32\wmpns.dll
2009-01-31 01:06:01 ----D---- C:\WINDOWS\Prefetch
2009-01-30 21:51:12 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-01-30 21:51:02 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-01-30 21:50:51 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-01-30 21:50:40 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-01-30 21:50:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-01-30 21:50:18 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-01-30 21:50:07 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-01-30 21:49:56 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-01-30 21:49:46 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-01-30 21:49:35 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-01-30 21:49:25 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-01-30 21:49:14 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-01-30 21:49:04 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-01-30 21:48:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-01-30 21:48:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-01-30 21:48:16 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-01-30 21:48:06 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-01-30 21:47:56 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-01-30 21:42:13 ----D---- C:\WINDOWS\system32\scripting
2009-01-30 21:42:10 ----D---- C:\WINDOWS\l2schemas
2009-01-30 21:42:09 ----D---- C:\WINDOWS\system32\en
2009-01-30 21:42:09 ----D---- C:\WINDOWS\system32\bits
2009-01-30 21:37:27 ----D---- C:\WINDOWS\network diagnostic
2009-01-30 21:24:45 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-01-30 21:23:01 ----A---- C:\WINDOWS\system32\MRT.exe
2009-01-29 21:56:01 ----D---- C:\Documents and Settings\Administrator\Application Data\TeamViewer
2009-01-29 10:25:14 ----A---- C:\WINDOWS\system32\tsccvid.dll
2009-01-29 10:25:11 ----D---- C:\WINDOWS\system32\QuickTime
2009-01-29 10:25:03 ----D---- C:\Documents and Settings\All Users\Application Data\TechSmith
2009-01-29 10:24:39 ----D---- C:\Program Files\Common Files\TechSmith Shared
2009-01-29 10:24:35 ----D---- C:\Program Files\TechSmith
2009-01-29 03:04:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2009-01-29 03:04:15 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2009-01-29 03:04:07 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2009-01-29 03:03:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2009-01-29 03:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB935448$
2009-01-29 03:03:41 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-01-29 03:03:23 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2009-01-29 03:02:44 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2009-01-29 03:02:35 ----HDC---- C:\WINDOWS\$NtUninstallKB951698_0$
2009-01-29 03:02:27 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$
2009-01-29 03:02:07 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$
2009-01-29 03:01:58 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-01-29 03:01:51 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2009-01-29 03:01:43 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
2009-01-29 03:01:35 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-01-29 03:01:27 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2009-01-29 03:01:19 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2009-01-29 03:01:10 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2009-01-29 03:01:02 ----D---- C:\WINDOWS\ie7updates
2009-01-29 03:00:54 ----HDC---- C:\WINDOWS\$NtUninstallKB938464_0$
2009-01-29 03:00:46 ----HDC---- C:\WINDOWS\$NtUninstallKB954600_0$
2009-01-29 03:00:38 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2009-01-29 03:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2009-01-29 03:00:19 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2009-01-28 19:59:50 ----N---- C:\WINDOWS\system32\xpsp3res.dll
2009-01-28 19:59:46 ----N---- C:\WINDOWS\system32\wmphoto.dll
2009-01-28 19:59:43 ----N---- C:\WINDOWS\system32\wlanapi.dll
2009-01-28 19:59:43 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2009-01-28 19:59:43 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2009-01-28 19:59:41 ----N---- C:\WINDOWS\system32\verclsid.exe
2009-01-28 19:59:39 ----N---- C:\WINDOWS\system32\tspkg.dll
2009-01-28 19:59:39 ----N---- C:\WINDOWS\system32\tsgqec.dll
2009-01-28 19:59:31 ----N---- C:\WINDOWS\system32\setupn.exe
2009-01-28 19:59:29 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2009-01-28 19:59:28 ----N---- C:\WINDOWS\system32\rasqec.dll
2009-01-28 19:59:27 ----N---- C:\WINDOWS\system32\qutil.dll
2009-01-28 19:59:26 ----N---- C:\WINDOWS\system32\qcliprov.dll
2009-01-28 19:59:26 ----N---- C:\WINDOWS\system32\qagentrt.dll
2009-01-28 19:59:26 ----N---- C:\WINDOWS\system32\qagent.dll
2009-01-28 19:59:26 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2009-01-28 19:59:24 ----N---- C:\WINDOWS\system32\onex.dll
2009-01-28 19:59:19 ----N---- C:\WINDOWS\system32\napstat.exe
2009-01-28 19:59:19 ----N---- C:\WINDOWS\system32\napmontr.dll
2009-01-28 19:59:19 ----N---- C:\WINDOWS\system32\napipsec.dll
2009-01-28 19:59:18 ----N---- C:\WINDOWS\system32\msxml6r.dll
2009-01-28 19:59:18 ----N---- C:\WINDOWS\system32\msxml6.dll
2009-01-28 19:59:16 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2009-01-28 19:59:16 ----N---- C:\WINDOWS\system32\mssha.dll
2009-01-28 19:59:06 ----N---- C:\WINDOWS\system32\mmcperf.exe
2009-01-28 19:59:06 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2009-01-28 19:59:05 ----N---- C:\WINDOWS\system32\mmcex.dll
2009-01-28 19:59:05 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2009-01-28 19:58:59 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2009-01-28 19:58:59 ----N---- C:\WINDOWS\system32\kmsvc.dll
2009-01-28 19:58:59 ----N---- C:\WINDOWS\system32\kbdpash.dll
2009-01-28 19:58:59 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2009-01-28 19:58:59 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2009-01-28 19:58:59 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2009-01-28 19:58:53 ----N---- C:\WINDOWS\system32\smtpapi.dll
2009-01-28 19:58:53 ----N---- C:\WINDOWS\system32\rwnh.dll
2009-01-28 19:58:48 ----A---- C:\WINDOWS\005384_.tmp
2009-01-28 19:58:47 ----N---- C:\WINDOWS\system32\eapsvc.dll
2009-01-28 19:58:47 ----N---- C:\WINDOWS\system32\eapqec.dll
2009-01-28 19:58:47 ----N---- C:\WINDOWS\system32\eappprxy.dll
2009-01-28 19:58:47 ----N---- C:\WINDOWS\system32\eapphost.dll
2009-01-28 19:58:47 ----N---- C:\WINDOWS\system32\eappgnui.dll
2009-01-28 19:58:47 ----N---- C:\WINDOWS\system32\eappcfg.dll
2009-01-28 19:58:47 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2009-01-28 19:58:47 ----N---- C:\WINDOWS\system32\eapolqec.dll
2009-01-28 19:58:46 ----N---- C:\WINDOWS\system32\dot3ui.dll
2009-01-28 19:58:46 ----N---- C:\WINDOWS\system32\dot3svc.dll
2009-01-28 19:58:46 ----N---- C:\WINDOWS\system32\dot3msm.dll
2009-01-28 19:58:46 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2009-01-28 19:58:46 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2009-01-28 19:58:46 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2009-01-28 19:58:46 ----N---- C:\WINDOWS\system32\dot3api.dll
2009-01-28 19:58:46 ----N---- C:\WINDOWS\system32\dimsroam.dll
2009-01-28 19:58:46 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2009-01-28 19:58:45 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2009-01-28 19:58:45 ----N---- C:\WINDOWS\system32\credssp.dll
2009-01-28 19:58:44 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2009-01-28 19:58:44 ----N---- C:\WINDOWS\system32\azroles.dll
2009-01-28 19:58:41 ----N---- C:\WINDOWS\system32\aaclient.dll
2009-01-28 19:45:41 ----D---- C:\WINDOWS\system32\PreInstall
2009-01-28 19:45:40 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2009-01-28 19:35:21 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-01-28 16:59:57 ----D---- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2009-01-28 16:59:48 ----A---- C:\WINDOWS\system32\GEARAspi.dll
2009-01-28 16:59:26 ----D---- C:\Program Files\iPod
2009-01-28 16:59:23 ----D---- C:\Program Files\iTunes
2009-01-28 16:59:23 ----D---- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-28 16:59:10 ----D---- C:\Program Files\Bonjour
2009-01-28 16:58:34 ----D---- C:\Program Files\QuickTime
2009-01-28 16:58:32 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2009-01-28 16:58:20 ----D---- C:\Program Files\Apple Software Update
2009-01-28 16:58:15 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-01-28 16:57:52 ----D---- C:\Program Files\Common Files\Apple
2009-01-28 16:57:52 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
2009-01-28 16:01:35 ----D---- C:\Documents and Settings\Administrator\Application Data\InstallShield
2009-01-28 16:01:15 ----D---- C:\NVIDIA
2009-01-28 15:57:34 ----SHD---- C:\WINDOWS\Installer
2009-01-28 15:57:32 ----D---- C:\Documents and Settings\Administrator\Application Data\Identities
2009-01-28 15:57:26 ----HD---- C:\Program Files\Uninstall Information
2009-01-28 15:57:23 ----ASH---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2009-01-28 15:57:22 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2009-01-28 15:57:16 ----SHD---- C:\System Volume Information
2009-01-28 15:57:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-28 15:52:12 ----D---- C:\WINDOWS\system32\xircom
2009-01-28 15:52:12 ----D---- C:\Program Files\xerox
2009-01-28 15:52:12 ----D---- C:\Program Files\microsoft frontpage
2009-01-28 15:52:01 ----A---- C:\WINDOWS\control.ini
2009-01-28 15:52:01 ----A---- C:\AUTOEXEC.BAT
2009-01-28 15:51:57 ----A---- C:\WINDOWS\OEWABLog.txt
2009-01-28 15:51:54 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-01-28 15:51:20 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-28 15:51:20 ----RD---- C:\WINDOWS\Offline Web Pages
2009-01-28 15:51:20 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-01-28 15:51:16 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-01-28 15:51:13 ----D---- C:\Documents and Settings\Administrator\Application Data\Adobe
2009-01-28 15:51:06 ----D---- C:\WINDOWS\srchasst
2009-01-28 15:51:01 ----D---- C:\WINDOWS\system32\Macromed
2009-01-28 15:51:01 ----D---- C:\WINDOWS\system32\DirectX
2009-01-28 15:50:53 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-01-28 15:50:53 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-01-28 15:50:52 ----D---- C:\Program Files\Movie Maker
2009-01-28 15:50:40 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-01-28 15:50:40 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-01-28 15:50:40 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-01-28 15:50:40 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-01-28 15:50:39 ----A---- C:\WINDOWS\system32\atrace.dll
2009-01-28 15:50:37 ----A---- C:\WINDOWS\system32\desktop.ini
2009-01-28 15:50:36 ----A---- C:\WINDOWS\desktop.ini
2009-01-28 15:50:32 ----D---- C:\WINDOWS\system32\Restore
2009-01-28 15:50:32 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-01-28 15:50:32 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-01-28 15:50:31 ----D---- C:\Program Files\Windows Media Player
2009-01-28 15:50:31 ----A---- C:\WINDOWS\system32\srclient.dll
2009-01-28 15:50:31 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-01-28 15:50:31 ----A---- C:\WINDOWS\system32\ils.dll
2009-01-28 15:50:30 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-01-28 15:50:30 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-01-28 15:50:30 ----A---- C:\WINDOWS\system32\msconf.dll
2009-01-28 15:50:30 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-01-28 15:50:30 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-01-28 15:50:28 ----D---- C:\WINDOWS\PCHEALTH
2009-01-28 15:50:28 ----D---- C:\Program Files\NetMeeting
2009-01-28 15:50:28 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-01-28 15:50:27 ----D---- C:\Program Files\Common Files\Services